> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hookie.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Delivery health per destination: success rate, latency percentiles, error classes, time series

> Every attempt in the window, the failed ones and the successful ones, per destination in the project and in total. Answers which destination is failing, whether it refuses requests (4xx) or fails to serve them (5xx, timeouts), and how slow it is. The series is hourly for 24h and 7d, daily for 30d, with every bucket present.



## OpenAPI

````yaml /openapi.json get /admin/api/projects/{pid}/deliveries/metrics
openapi: 3.1.0
info:
  title: Hookie API
  version: 1.0.0
  summary: Capture, route and deliver webhooks.
  description: >-
    Hookie exposes three HTTP surfaces.


    **Ingest + streaming** is the public plane. A path-form endpoint URL
    authenticates by its own high-entropy slug — there is no key, token or
    cookie — and an `ik_live_…` ingest key authenticates the `/v1/*` routes. An
    endpoint URL files each payload into the endpoint's own dataset through the
    endpoint's own criteria and mappings (none means the whole payload, as one
    record); `/v1/ingest/{ingest_key}/{dataset}` stores the payload whole into
    the named dataset. Project mapping rules are evaluated on exactly one shape,
    `POST /v1/ingest/{ingest_key}` with no dataset segment, and never on an
    endpoint URL.


    **The customer portal API** is a separate, token-authed surface for your end
    customers, scoped to one portal and one customer.


    **The admin API** drives the console. It accepts either a browser session or
    an OAuth bearer token from a connected coding agent — the same routes, the
    same validation, the same audit trail. An agent's authority is its user's
    workspace role narrowed to the scopes granted in the console. It also
    accepts an **admin API key** (`hk_…`, Settings → API keys) for CI,
    infrastructure-as-code and vendor backends: the key acts as the member who
    created it, capped at the key's role (viewer, developer or admin — never
    billing or platform administration), optionally limited to one project, with
    an optional expiry and IP allowlist. Keys are stored as a SHA-256 hash and
    shown once; if their creator leaves the workspace they stop working. The
    same key works on the hosted MCP server at `/mcp`.


    **A refused agent is told how to proceed.** An agent's grant is one rung of
    a ladder — `hookie:read` < `hookie:write` < `hookie:manage` — and a call
    above it answers 403 with `code: "agent_scope_insufficient"`, the
    `required_scope`, the `granted_scopes` and a `manage_url` to the console
    page where its user widens it. When the user's own role is the limit the
    code is `insufficient_role` and there is no link, because no grant can
    exceed the user; billing, platform admin, managing connected agents and
    destination signing secrets answer `agent_not_permitted` at every scope. A
    human in the console still reads `Insufficient role`.


    **A suspended workspace** (an operator action, for abuse or non-payment)
    answers every surface with 403 and `reason: "workspace_suspended"`: ingest
    (endpoint URLs and ingest keys), `/v1/data` and `/v1/stream` refuse before
    anything is stored or counted, and every admin API write — console, OAuth
    agent or hosted MCP alike — is refused except billing, platform admin,
    connected-agent management, revoking an API key and the POST-bodied
    searches. The customer portal API is read-only in the same way: destination
    writes answer 403 `workspace_suspended`. Reads keep working. Nothing is sent
    while it is suspended: pending deliveries are paused, workflow runs already
    under way are paused, open `/v1/stream` connections are closed, and cron
    triggers, database sources and WebSocket listeners stop. Reinstating sends
    the paused deliveries, resumes the paused workflow runs where they stopped,
    and resumes the rest; no stored data is lost.


    **Rate limits.** `/admin/api/*` and `/mcp` allow 100 requests every 10
    seconds per credential — per API key, per connected agent, or per signed-in
    person. Over that, the answer is 429 with `Retry-After` (seconds).


    **Idempotency.** A `POST` to `/admin/api/*` may carry an `Idempotency-Key`
    header (1–255 printable characters, e.g. a UUID). The first request runs and
    its response is stored for 24 hours; a retry with the same key from the same
    credential, with the same path and body, gets that response back with
    `Idempotent-Replayed: true` and runs nothing. The same key with a different
    path, body or credential is refused with 422; a retry while the first
    request is still running gets 409. 5xx responses are not stored. `POST
    /admin/api/api-keys` refuses the header, because its response is a secret
    shown once and is never stored.


    **Versioning.** Every `/admin/api/*` and `/mcp` response carries
    `Hookie-Version` (currently `2026-09-29`). Additive changes — a new route, a
    new response field, a new optional parameter — ship under the current
    version, so clients must ignore fields they do not know. A breaking change
    gets a new dated version, announced in the changelog, and the previous
    version stays available for at least 12 months; a client pins one by sending
    `Hookie-Version` on its requests. A version this deployment does not serve
    is refused with 400 and the list of `supported_versions`.


    This document is generated from the request handlers and adversarially
    verified against them.
  contact:
    name: Hookie
    url: https://hookie.ai
  license:
    name: Proprietary
    url: https://hookie.ai/legal/terms
servers:
  - url: https://app.hookie.ai
    description: Production
  - url: https://app.preview.hookie.ai
    description: Preview
security: []
tags:
  - name: Ingest
    description: Send events to Hookie.
  - name: Streaming
    description: Tail events in real time over SSE or WebSocket.
  - name: Portal
    description: Token-authed surface for your end customers.
  - name: Projects
    description: Projects and their settings.
  - name: Routing
    description: Rules, endpoints, datasets and records.
  - name: Delivery
    description: Destinations, deliveries and replay.
  - name: Workflows
    description: Multi-step workflows, triggers and AI agents.
  - name: Observability
    description: Search, correlation, stats and the audit log.
  - name: Workspace
    description: Members, connected agents, SSO and billing.
  - name: Data API
    description: >-
      Read-only access to the datasets and columns a project exposes, with
      per-project keys.
  - name: Broadcast Logs
    description: >-
      Forward a project's logs and traces over OTLP/HTTP (JSON) to Datadog,
      Grafana Cloud, an OpenTelemetry Collector, PostHog or Sentry.
paths:
  /admin/api/projects/{pid}/deliveries/metrics:
    get:
      tags:
        - Deliveries
      summary: >-
        Delivery health per destination: success rate, latency percentiles,
        error classes, time series
      description: >-
        Every attempt in the window, the failed ones and the successful ones,
        per destination in the project and in total. Answers which destination
        is failing, whether it refuses requests (4xx) or fails to serve them
        (5xx, timeouts), and how slow it is. The series is hourly for 24h and
        7d, daily for 30d, with every bucket present.
      operationId: getDeliveryMetrics
      parameters:
        - name: pid
          in: path
          required: true
          description: Project id (UUID) belonging to the caller workspace.
          schema:
            type: string
        - name: window
          in: query
          schema:
            type: string
            enum:
              - 24h
              - 7d
              - 30d
            default: 24h
        - name: destination_id
          in: query
          description: Only this destination.
          schema:
            type: string
      responses:
        '200':
          description: Delivery health for the window.
          content:
            application/json:
              schema:
                type: object
                required:
                  - window
                  - since
                  - until
                  - destination_id
                  - bucket
                  - bucket_ms
                  - totals
                  - destinations
                  - series
                properties:
                  window:
                    type: string
                    enum:
                      - 24h
                      - 7d
                      - 30d
                  since:
                    type: string
                    format: date-time
                  until:
                    type: string
                    format: date-time
                  destination_id:
                    type:
                      - string
                      - 'null'
                  bucket:
                    type: string
                    enum:
                      - hour
                      - day
                  bucket_ms:
                    type: integer
                  totals:
                    type: object
                    required:
                      - deliveries
                      - success_rate
                      - attempts
                      - attempts_ok
                      - attempt_success_rate
                      - latency_ms
                      - errors
                    properties:
                      deliveries:
                        type: object
                        required:
                          - total
                          - delivered
                          - failed
                          - pending
                        description: >-
                          Deliveries created in the window, by where they ended
                          up.
                        properties:
                          total:
                            type: integer
                          delivered:
                            type: integer
                          failed:
                            type: integer
                            description: Dead, or failed with no retry ahead of it.
                          pending:
                            type: integer
                            description: Queued, paused, or failed with a retry scheduled.
                      success_rate:
                        type:
                          - number
                          - 'null'
                        description: >-
                          delivered / (delivered + failed). Null until a
                          delivery has finished.
                      attempts:
                        type: integer
                        description: Attempts made in the window.
                      attempts_ok:
                        type: integer
                        description: Attempts that got a 2xx.
                      attempt_success_rate:
                        type:
                          - number
                          - 'null'
                      latency_ms:
                        type: object
                        required:
                          - p50
                          - p95
                          - p99
                        description: >-
                          Nearest-rank percentiles over every attempt's latency
                          in the window, failed attempts included: a timeout
                          counts as its timeout.
                        properties:
                          p50:
                            type:
                              - integer
                              - 'null'
                          p95:
                            type:
                              - integer
                              - 'null'
                          p99:
                            type:
                              - integer
                              - 'null'
                      errors:
                        type: object
                        required:
                          - 3xx
                          - 4xx
                          - 5xx
                          - timeout
                          - connection
                          - other
                        description: >-
                          Failed attempts in the window by class. timeout: no
                          answer within the destination's timeout; connection:
                          refused, reset, DNS or TLS.
                        properties:
                          3xx:
                            type: integer
                          4xx:
                            type: integer
                          5xx:
                            type: integer
                          timeout:
                            type: integer
                          connection:
                            type: integer
                          other:
                            type: integer
                  destinations:
                    type: array
                    items:
                      type: object
                      required:
                        - destination_id
                        - destination_name
                        - enabled
                        - deliveries
                        - success_rate
                        - attempts
                        - attempts_ok
                        - attempt_success_rate
                        - latency_ms
                        - errors
                      properties:
                        destination_id:
                          type: string
                        destination_name:
                          type:
                            - string
                            - 'null'
                          description: >-
                            Null for a destination deleted since, whose history
                            is still in the window.
                        enabled:
                          type: boolean
                        deliveries:
                          type: object
                          required:
                            - total
                            - delivered
                            - failed
                            - pending
                          description: >-
                            Deliveries created in the window, by where they
                            ended up.
                          properties:
                            total:
                              type: integer
                            delivered:
                              type: integer
                            failed:
                              type: integer
                              description: Dead, or failed with no retry ahead of it.
                            pending:
                              type: integer
                              description: >-
                                Queued, paused, or failed with a retry
                                scheduled.
                        success_rate:
                          type:
                            - number
                            - 'null'
                          description: >-
                            delivered / (delivered + failed). Null until a
                            delivery has finished.
                        attempts:
                          type: integer
                          description: Attempts made in the window.
                        attempts_ok:
                          type: integer
                          description: Attempts that got a 2xx.
                        attempt_success_rate:
                          type:
                            - number
                            - 'null'
                        latency_ms:
                          type: object
                          required:
                            - p50
                            - p95
                            - p99
                          description: >-
                            Nearest-rank percentiles over every attempt's
                            latency in the window, failed attempts included: a
                            timeout counts as its timeout.
                          properties:
                            p50:
                              type:
                                - integer
                                - 'null'
                            p95:
                              type:
                                - integer
                                - 'null'
                            p99:
                              type:
                                - integer
                                - 'null'
                        errors:
                          type: object
                          required:
                            - 3xx
                            - 4xx
                            - 5xx
                            - timeout
                            - connection
                            - other
                          description: >-
                            Failed attempts in the window by class. timeout: no
                            answer within the destination's timeout; connection:
                            refused, reset, DNS or TLS.
                          properties:
                            3xx:
                              type: integer
                            4xx:
                              type: integer
                            5xx:
                              type: integer
                            timeout:
                              type: integer
                            connection:
                              type: integer
                            other:
                              type: integer
                    description: >-
                      The project's destinations, busy or not, then any deleted
                      one with history in the window.
                  series:
                    type: array
                    items:
                      type: object
                      required:
                        - t
                        - ok
                        - failed
                      properties:
                        t:
                          type: string
                          format: date-time
                          description: Start of the bucket (UTC).
                        ok:
                          type: integer
                        failed:
                          type: integer
        '400':
          description: window is not 24h, 7d or 30d.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: >-
            Not signed in, or the agent bearer token is invalid, unknown or
            revoked.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: >-
            Email domain not allowed for the workspace, or an agent token
            granted no Hookie scope.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          description: Internal error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: string
          description: Human-readable reason.
        retry_after:
          type: integer
          description: Seconds to wait. Present on 429.
        upgrade_url:
          type: string
          format: uri
          description: Present only on a monthly-quota 429.
        reason:
          type: string
          description: >-
            Machine-readable reason, where the status alone is ambiguous.
            `workspace_suspended` (403): the workspace is suspended;
            `delivery_allowance_exhausted` (429): a replay was refused because
            the monthly delivery allowance is used. `endpoint_disabled` (503):
            the endpoint is switched off; `handshake_failed`: a provider
            URL-verification challenge could not be answered (#193).
            `missing_header`, `bad_signature`, `stale_timestamp` (401): an
            endpoint's provider signature check failed; `scheme` names the
            check.
        code:
          type: string
          enum:
            - agent_scope_insufficient
            - insufficient_role
            - agent_not_permitted
          description: >-
            Present on a 403 to an OAuth-connected agent.
            `agent_scope_insufficient`: the agent's grant is below what the call
            needs, and widening it would let the call through (see
            `required_scope` and `manage_url`). `insufficient_role`: the user's
            OWN workspace role does not allow the call, so no grant can — a
            workspace owner or admin has to change the role.
            `agent_not_permitted`: no connected agent may do this at any scope
            (billing, platform admin, managing connected agents, a destination's
            signing secret).
        required_scope:
          type: string
          enum:
            - hookie:read
            - hookie:write
            - hookie:manage
          description: 'With `code`: the scope the refused call needs.'
        granted_scopes:
          type: array
          items:
            type: string
          description: 'With `code`: the scopes the agent''s grant holds now.'
        manage_url:
          type: string
          format: uri
          description: >-
            With `code: "agent_scope_insufficient"` only: the console's Settings
            → Connected agents page, opened on this agent
            (`…/#/settings/agents?client=<client_id>`), where its user widens
            the grant. The change applies on the agent's next request.
        scheme:
          type: string
          description: 'Present on a signature 401: the endpoint''s verification scheme.'
  responses:
    RateLimited:
      description: >-
        Over this credential's limit (100 requests per 10 seconds). Retry after
        `Retry-After` seconds.
      headers:
        Retry-After:
          schema:
            type: integer
          description: Seconds to wait.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'

````